CVE-2022-45065: WordPress SEO Plugin by Squirrly SEO Plugin <= 12.1.20 is vulnerable to Cross Site Scripting (XSS)
Published May 8, 2023
·Updated
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Squirrly SEO Plugin by Squirrly SEO plugin <= 12.1.20 versions.
Affected Software
1 affected component
Squirrly SEO Plugin by Squirrly SEO WordPress<=12.1.20
Remediation
Information
Update to 12.1.21 or a higher version.
Event History
May 8, 2023
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
RemedyDescriptionSeverityWeakness
Data Sourced
03:15 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-45065?
CVE-2022-45065 has a medium severity rating due to its potential for unauthorized reflected cross-site scripting attacks.
2
How do I fix CVE-2022-45065?
To fix CVE-2022-45065, update the Squirrly SEO Plugin to version 12.1.21 or higher.
3
What are the implications of CVE-2022-45065?
CVE-2022-45065 allows attackers to execute arbitrary scripts in the context of a website, compromising user data and sessions.
4
Which versions of the Squirrly SEO Plugin are affected by CVE-2022-45065?
CVE-2022-45065 affects all versions of the Squirrly SEO Plugin prior to version 12.1.21.
5
Is CVE-2022-45065 a common vulnerability?
Cross-site scripting vulnerabilities like CVE-2022-45065 are relatively common in web applications and can occur if proper input validation is not implemented.